Google Consent Mode v2
Set up Google Consent Mode with GoTrust
Everything you need to use Google Consent Mode v2 with the GoTrust consent banner: a quick start, then the reference — default signals, Basic and Advanced configuration, banner requirements, Google Tag Gateway and debugging.
Quick start
Google Consent Mode is on by default in GoTrust — there's nothing to switch on. Five steps take you from a new site to a checked setup:
- Add your website. In the GoTrust dashboard, open Cookie Consent Management and add your domain. Then follow its setup steps: cookie categories, banner, languages and the Consent Code.
- Install GoTrust in one of two ways:
- Script tag: copy the code from the Consent Code step and place it first in your page's
<head>, before any Google tag. - Google Tag Manager: add the GoTrust GTM template and fire it on the Consent Initialization - All Pages trigger.
- Script tag: copy the code from the Consent Code step and place it first in your page's
- Make the banner meet Google's requirements with the recommended template — steps. Using IAB TCF? In Customize Banner, open the IAB TCF v2.2 / ATP tab and turn on Enable IAB TCF and Enable Google Advertiser Consent Mode, which sets Google's
enableAdvertiserConsentModeflag on the TC data. Either way, GoTrust sets its Google developer ID automatically. - Choose Basic or Advanced consent mode for your Google tags — how to configure each.
- Check your setup. Open your site with
?gt-shim-debug=1and look for the GoTrust debug message in the browser console, then confirm the default and update commands in Google Tag Assistant — debug mode.
Not legal advice. This page documents GoTrust's technical implementation of Google Consent Mode. It explains how the product behaves and how to configure it — it does not constitute legal advice and does not, on its own, guarantee compliance with any privacy regulation. Consult your own legal counsel for compliance obligations specific to your organization.
Overview
GoTrust's cookie consent banner sets Google Consent Mode v2 signals before any Google tag can fire, restores returning visitors' prior choices, and pushes consent updates to the page's dataLayer as visitors make choices. It can be installed either as a direct script embed or as a Google Tag Manager Community Template — both paths converge on the same consent logic. This page follows the explanations Google publishes for Consent Mode; where our behavior diverges or adds something GoTrust-specific, it's called out explicitly.
Google references:
- Set up consent mode (Google developer guide)
- Consent mode overview
- Consent mode reference (signal types)
- Google's Additional Consent technical specification
- About Google tag gateway for advertisers
- Troubleshoot consent mode with Tag Assistant
- Data transmission controls
- Google's privacy information for sites and apps
Consent signal reference
All seven Consent Mode v2 signal types are implemented. The initial default is sent as two calls: everything granted globally, then everything except security_storage denied for visitors in the EEA, UK and Switzerland, using the region parameter. The descriptions below are Google's.
| Signal | Purpose | Default | Notes |
|---|---|---|---|
ad_storage | Enables storage, such as cookies (web) or device identifiers (apps), related to advertising. | Denied | Denied by default in the EEA, UK and Switzerland; granted elsewhere until the visitor makes a choice |
analytics_storage | Enables storage, such as cookies (web) or device identifiers (apps), related to analytics, for example, visit duration. | Denied | Denied by default in the EEA, UK and Switzerland; granted elsewhere until the visitor makes a choice |
functionality_storage | Enables storage that supports the functionality of the website or app, for example, language settings. | Denied | Denied by default in the EEA, UK and Switzerland; granted elsewhere until the visitor makes a choice |
personalization_storage | Enables storage related to personalization, for example, video recommendations. | Denied | Denied by default in the EEA, UK and Switzerland; granted elsewhere until the visitor makes a choice |
security_storage | Enables storage related to security such as authentication functionality, fraud prevention, and other user protection. | Granted | Always granted |
ad_user_data | Sets consent for sending user data to Google for online advertising purposes. | Denied | Denied by default in the EEA, UK and Switzerland; granted elsewhere until the visitor makes a choice |
ad_personalization | Sets consent for personalized advertising. | Denied | Denied by default in the EEA, UK and Switzerland; granted elsewhere until the visitor makes a choice |
Basic vs. Advanced mode
Basic configuration blocks Google tags before consent; advanced configuration does not. In Basic mode, Google tags are blocked until the user interacts with the consent banner: no data is sent before a user consents — not even the default consent status. In Advanced mode, Google tags load when a user opens the website or app, with the default consent states set; while consent is denied, tags send measurements without cookies, which Google uses for modeling. Google explains both in its consent mode developer guide.
Which of the two applies to a given tag is ultimately that tag's own setting (Google Ads, GA4, and GTM tags each expose this under their own Consent Settings / "Additional Consent Checks") — no CMP can override it directly. What the GoTrust GTM template's Consent Mode Type field controls is the companion piece a CMP is responsible for: how long GTM's wait_for_update window stays open while evaluating the default state this template sets, so it lines up with whichever of the two the customer has chosen for their tags.
wait_for_update is set from the waitForUpdateMs field (default 2000 ms). Google describes wait_for_update as controlling how long to wait before data is sent; the wait gives the GoTrust banner time to apply a returning visitor's stored choice.
Configuring Basic and Advanced
How you choose depends on how your Google tags are added to the site.
GTM container added in the GoTrust dashboard
Go to Cookie Consent Management → your domain → Customize Banner, open the Google Tag Manager tab, turn on Enable Google Tag Manager and add your container ID. Then set Consent Mode:
- Basic — GoTrust loads the container only after the visitor consents, so its Google tags are blocked until then.
- Advanced — GoTrust loads the container immediately, with the default consent states set. Wait for Update (ms) sets
wait_for_update.
GoTrust GTM template (Google tags in your own GTM container)
- Basic — on each Google tag, open Advanced Settings → Consent Settings, choose Require additional consent for tag to fire and add the consent types it needs (for example
analytics_storagefor Google Analytics,ad_storageandad_user_datafor Google Ads). Fire the tag on a Custom Event trigger with event namegotrust_consent_updateinstead of a page-view trigger. GoTrust pushes this event after every consent update — when the visitor makes a choice, and on each page for returning visitors — so the tag fires once consent is granted. In the GoTrust tag, set Consent Mode Type to Basic. - Advanced — keep your Google tags on their usual triggers with no additional consent required; they load with the default consent states set. In the GoTrust tag, set Consent Mode Type to Advanced.
GoTrust script tag with Google tags in your page HTML
- Basic — mark each Google tag script so GoTrust holds it until the visitor grants that category, then runs it:
<script type="text/plain" data-original-type="text/javascript"
data-consent-category="analytics" async
src="https://www.googletagmanager.com/gtag/js?id=G-XXXXXXX"></script>
<script type="text/plain" data-original-type="text/javascript"
data-consent-category="analytics">
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
gtag('js', new Date());
gtag('config', 'G-XXXXXXX');
</script>- Advanced — add your Google tag as usual, after the GoTrust script. GoTrust sets the default consent states before it loads and sends an update when the visitor makes a choice.
Turning Consent Mode off
If you don't want GoTrust to send Consent Mode commands at all, add data-consent-mode="off" to the GoTrust script tag in your page:
<script src=".../gotrust-consent-shim.js" data-safe="true" data-consent-mode="off"></script>GoTrust then sends no Consent Mode default or update commands (and no url_passthrough, ads_data_redaction or developer ID), and blocks Google's tag scripts (gtag.js and Google Tag Manager) until the visitor grants analytics or marketing consent — Basic behavior without Consent Mode. Remove the attribute to switch Consent Mode back on. This applies to the HTML embed; the GoTrust GTM template always uses Consent Mode.
Banner requirements
What the GoTrust banner does
Configurable per domain from the GoTrust dashboard.
- Banner copy, layout, and consent categories are fully configurable through the dashboard UI — no code changes required per domain.
- When Consent Mode is enabled without IAB TCF, the dashboard proactively recommends a banner template that follows Google's recommendations: it names personalization and analytics use, links directly to business.safety.google/privacy within the banner itself — not a separate linked page — and frames consent as an affirmative action.
- Consent is only recorded on an explicit visitor action (Accept / Reject / Save preferences) — never inferred from scrolling, continued browsing, or a timeout.
- The banner appears globally: every domain has a default banner, shown to new visitors in any country that has no regional banner of its own. As a safeguard, if no banner applies to a visitor's country, GoTrust sends a Consent Mode update granting all consent types, so measurement continues even if your global consent defaults are denied. This never happens in the EEA, UK or Switzerland, when the visitor's country can't be determined, or when the browser sends Global Privacy Control, and it is not recorded as a visitor choice.
Creating a banner that meets Google's requirements
- Apply the template. In Cookie Consent Management → your domain → Customize Banner, find Banner Description. With IAB TCF off, a Recommended: Google-compliant banner template notice appears there — click Use Recommended Template.
- What it includes. The text explains that data is used to personalize content and ads and for analytics, includes the link https://business.safety.google/privacy in the banner itself, and asks for affirmative consent through the Allow all button.
- If you edit the text, keep all three parts. The link must stay inside the banner, not only on a separate page the banner links to. If you rename the Allow all button, update the sentence that mentions it.
- Keep the Allow all button switched on — it's the affirmative consent option.
- Other languages: translate the banner in the Language Support step, keeping the link.
With IAB TCF on, the banner shows the TCF disclosure and purposes instead.
Google Tag Gateway & consent timing
Google Tag Gateway (GTG) lets Google tags be served from your own first-party domain instead of googletagmanager.com. It changes where a tag is served from, not how consent works — but it can change when a tag becomes available, which is the part that matters here.
What can go wrong
One-click CDN injection (Cloudflare, Akamai, Fastly, and similar automated GTG setups) writes routing rules directly into your CDN configuration — outside your page's own script order — which often prevents you from controlling the order in which scripts load. That makes it possible for a GTG-served tag to become active before GoTrust's consent default command has run, since your CDN controls that timing, not your HTML. This is a late consent signal: the tag was reachable before a default had been established for it.
Checking whether a tag is enrolled in GTG
- Check the tag's own status in its Google UI. Google Ads, GA4, and GTM each show a serving-domain status (first-party / active) for tags using GTG, in that product's own tag settings.
- Cross-check with Tag Assistant. Open the Summary panel → Output → Hits Sent. If requests are going to your own domain rather than
googletagmanager.com, GTG is active for that tag. See Troubleshoot consent mode with Tag Assistant.
If GoTrust flags a late signal and GTG is confirmed
Three ways to resolve it, in order of how much control you want over load order:
Keep current setup
Adopt U+C (advanced consent mode)
Move the affected container to advanced consent mode (U+C) and configure Data Transmission Controls and Global Consent Defaults according to your needs — for example, only for the regions where you deny consent by default (such as the EEA, UK and Switzerland) rather than globally. Where no GoTrust banner is shown, GoTrust grants consent so measurement continues (see Banner requirements). U+C doesn't depend on script order, so GTG-controlled timing stops being a problem.
Consolidate
Migrate into one GTM container
Move the affected tags into a single GTM container and deploy that container via GTG, so GoTrust's Consent Initialization trigger governs the whole container's timing again.
Full control
Configure GTG manually
Set up GTG through your CDN/server manually instead of one-click injection, so you — not the automated integration — control script import order.
Why U+C is the recommended default. Of the three, U+C is recommended first for GTG-enabled tags because it's compatible with manual GTG setups too — it works regardless of which of the three paths above you end up on, since it never depended on load order to begin with.
Misconfiguration debug mode
GoTrust's script includes a debug mode that checks your own installation for the exact failure mode described above — a Google tag positioned or firing before the consent default was set.
- Enable it. Open your site with
?gt-shim-debug=1appended to the URL, then open the browser console. - Read the result. If the setup is correct, you see
[GoTrust Shim] Debug: OK — the Consent Mode default and TCF stub were set before any Google tag on this page. If a Google tag loaded or ran first, you see a[GoTrust Shim] MISCONFIGURATION DETECTED:warning naming what was found: a Google or ad-tech script placed above the GoTrust script, a Google tag that had already run, or a dataLayer that already had entries. - Check Google Tag Gateway first. A flagged late signal may come from a tag that uses GTG, which serves it from your own domain. Use the steps in Google Tag Gateway & consent timing to check whether the flagged tag uses GTG.
- Act on it. GTG confirmed: follow one of the three paths in Google Tag Gateway & consent timing. No GTG involved: move the GoTrust script tag earlier in
<head>, above any other tag-management snippet.
With the GoTrust GTM template, the template sets the default on the Consent Initialization trigger, so debug mode reports that instead — check in Tag Assistant that it fires before your other tags.
Normal visitors never see this — the checks are silent unless the query parameter is present.
Developer ID
Both the GTM Community Template and the direct script embed set Google's developer ID after the Consent Mode defaults are established: gtag('set', 'developer_id.dNGZkOW', true).




